Skip to content
LeakLens

Which data breaches exposed your email?

Check it below, then go further: test passwords against known leaks, find accounts by username, look up IP and DNS records, and scan website security headers.

57 incidents indexed · nothing you type is stored · no account needed

Tools

Each tool does one job. Pick one, enter what you want to check, get the result.

Why LeakLens exists

Checking whether your email appears in a breach should not require trading one privacy problem for another. Many services ask you to create an account, verify the address, and then upsell monitoring you never asked for. LeakLens takes the opposite approach: type what you want to check, get a straight answer, and the input is discarded from memory as soon as the response is sent. No profiles, no mailing lists, no checkout flows.

The toolkit grew from auditing our own footprints. A reused username that still had a public profile on a forgotten forum, an old password that showed up in a public leak corpus, a domain that sent mail without any authentication. Each is easy to miss individually but trivial to check mechanically. Bundling those checks into one privacy-preserving place means you can run a quarterly review in the time it takes to watch one video.

Every interactive tool is paired with education written at the same level of care. The twelve guides in the library, from breach response playbooks to SPF/DKIM/DMARC explainers, broker opt-out workflows and DNS security primers, are not summaries of other blogs. They are original articles written from primary sources, tested against live behaviour, dated with published and updated timestamps and interlinked with the tools that let you act on what you read.

Operationally, the site is intentionally boring: lookups run in memory, passwords are checked via k-anonymity so the full secret never leaves your device, and rate limiting is per-IP without central tracking. Advertising loads only after you explicitly accept it, which is why the experience is identical whether you enable it or keep essential-only. Independence matters for credibility, so we publish our methodology, our breach inclusion criteria, our testing notes and our contact address rather than hiding behind anonymous copy.

Queries aren't saved

Lookups run in memory while your request is processed, then the input is gone.

Passwords stay in your browser

The password check uses k-anonymity: only a five-character fragment of a hash is sent out.

No premium tier

Ads cover the hosting bill. There are no paywalls and there won't be.

How we keep this site trustworthy

  • Each breach record is vetted against primary reporting, company disclosure, regulatory filing or reputable independent investigation, not by ingesting rumoured dumps. An incident appears only when its scale and exposed data types can be stated accurately.
  • Tools distinguish honest uncertainty from guessing: if a provider is unreachable or a platform sits behind a bot wall, the result shows "unavailable" or "inconclusive" rather than inventing an answer.
  • Guides are dated and maintained. You will find both a published and an updated date on every article, and a description of what changed when the underlying technology or advice materially evolved.
  • The codebase is open source under MIT. Rate limits, SSRF guards and CSP policies are inspectable rather than asserted.

Read more on our about page, privacy policy and terms. Questions and correction requests go to contact. We respond within two business days.

Common questions

Is LeakLens free?

Yes. Every tool works without an account or payment. Hosting costs are covered by advertising, which only loads after you opt in through the cookie banner.

Do you store the email addresses or passwords I check?

No. Breach lookups run in memory against our index and are then discarded, nothing is written to disk or logs. The password checker never sends your password anywhere; only a short hash fragment leaves your browser.

What do these tools actually tell me?

Which major breaches involve your email's domain or provider, whether a specific password appears in known leak lists, where a username has public profiles, who an IP address belongs to, and how a website's security headers are configured.

Can I look up other people?

The tools only show what is already public. Using them to harass, stalk or expose anyone violates our terms, they are meant for checking your own exposure, verifying brand handles, and lawful research.